Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Synchronise 2023.1 with upstream #348

Merged
merged 1 commit into from
Nov 18, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions ansible/inventory/group_vars/all/proxy
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,4 @@ no_proxy:
- "127.0.0.1"
- "localhost"
- "{{ ('http://' ~ docker_registry) | urlsplit('hostname') if docker_registry else '' }}"
- "{{ kolla_internal_vip_address }}"
5 changes: 3 additions & 2 deletions etc/kayobe/proxy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,9 @@

# List of domains, hostnames, IP addresses and networks for which no proxy is
# used. Defaults to ["127.0.0.1", "localhost", "{{ ('http://' ~
# docker_registry) | urlsplit('hostname') }}"] if docker_registry is set, or
# ["127.0.0.1", "localhost"] otherwise. This is configured only if either
# docker_registry) | urlsplit('hostname') }}","{{ kolla_internal_vip_address
# }}"] if docker_registry is set, or ["127.0.0.1", "localhost","{{
# kolla_internal_vip_address }}"] otherwise. This is configured only if either
# http_proxy or https_proxy is set.
#no_proxy:

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
features:
- |
Adds the internal VIP to the NOPROXY/noproxy environment variables.
security:
- |
When running API requests from a host configured with kayobe, traffic
destined for the internal VIP is sent via the default proxy. This can be a
security issue if not using TLS as the proxy will be able to intercept the
traffic. If using an untrusted proxy, with TLS disabled on the internal
VIP, it is recommended that you run ``kayobe overcloud host configure -t
proxy``, ``kayobe seed hypervisor host configure -t proxy``, ``kayobe seed
host configure -t proxy``, and ``kayobe infra vm host configure -t proxy``,
to add the internal VIP to the no proxy configuration. This is considered a
minor issue as traffic between containers will not use the proxy by
default.
`LP#2087556 <https://launchpad.net/bugs/2087556>`__